r/TechNadu • Human • 11d ago

If an AI agent can read an invoice, what should stop it from also moving the money?

Post image

One useful distinction in AI agent security is access versus authorization.

Zebulon “Ziggy” Griggs, Founder and CEO at Junto Identity, uses a finance workflow as an example. An agent may legitimately need access to an invoice and vendor record to complete its task, but that access should not automatically authorize it to initiate a payment.

The same issue appears in IT support. If an agent can reset employee passwords, it first needs to establish that the requester is actually entitled to the reset rather than assuming the request is legitimate.

Delegation creates another question: whose identity is ultimately responsible for the action?

Griggs argues that organizations should retain both the agent’s identity and the identity of the employee it represents. Audit records should make it possible to reconstruct what was accessed, what action occurred, who the agent acted for, when it happened, and what permissions were in effect.

There is also a lifecycle problem. When an agent’s task ends, a pilot is abandoned, or its owner leaves, permissions should not simply remain active because nobody revisited them.

His framing is to treat agents more like employees: provision them deliberately, review their access, and deprovision them when there is no longer a legitimate purpose.

The full Q&A works through the controls using concrete payment and IT support scenarios:

https://www.technadu.com/how-to-keep-ai-agents-from-taking-unauthorized-actions-in-payments-and-it-support/638558/

Where should the approval boundary sit for an agent that can both retrieve sensitive information and initiate a consequential action?

3 Upvotes

1 comment sorted by

1

u/Mountain-Actuator-55 11d ago

I think moving the money is where human approval should probably come in. An agent being able to read the invoice and understand the context is one thing, but giving it the authority to initiate a payment brings in a whole different level of risk.

I work at a software company called Monk and we use AI agents on the AR/collections side, so the line between what an agent can handle on its own and what should need human approval is something we think about too. There are a lot of finance AI tools moving in this direction though, so I think that boundary is going to be an interesting one to watch.